Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Fortinet FortiAnalyzer: CVE-2024-36508: Multiple arbitrary file deletion in the CLI

Severity
6
CVSS
(AV:L/AC:L/Au:M/C:N/I:C/A:C)
Published
Feb 11, 2025
Added
Aug 1, 2025
Modified
May 26, 2026

Description

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiManager and FortiAnalyzer CLI may allow any authenticated admin user with diagnose privileges to delete any file on the system.

Solution

fortinet-fortianalyzer-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.